Many think that passwords with random characters are more secure.

Truth is: "four random common words" make the best password - secure and easy to remembers! 🔒

What is your password strategy?

Here are more facts about passwords and security: 👇

https://tutanota.com/blog/posts/how-create-strong-password

Reply to this note

Please Login to reply.

Discussion

For strong memorable passwords, use phrases.

Longer is better. If there's no character limit then tell a 1-2 sentence story, something secret that only you know. All lower case no spaces. A 100 character password is going to be really hard to brute force even if the attacker is operating on the assumption that you only used lower case letters.

It's also pretty easy for you to remember if it's a phrase about a secret personal experience.

nostr:nevent1qqst8gerzyyjj62g2wauue0qplus6tlae7s4g5t5pkpxln0ujh347yqpz3mhxue69uhhyetvv9ujuerpd46hxtnfdupzpqll3nws4xv5rp4plrzryf5e6vphh577hvdl66657ad2ty2u20djqvzqqqqqqykuxhrr

And the key here is “random”. And people are not designed to produce truly random data out if the box

If only there were some kind of program that could do that for you…

There are many secure password generators and many apps require stronger passwords but the majority of passwords are “qwerty123” and alike

The point here is, you must introduce complexity into your password and different mechanics (mnemonics, special characters, secret words etc) can’t render this fact unnecessary

Yes, I was being sarcastic.

Anyone can memorize a strong password and use that to secure their password manager. Most people won't.

Not just “many”. Nearly every single tech company thinks you need to have a ridiculous mix of punctuation, letters, and numbers, and that they somehow should expire every few months.

Very useful post. Thanks for sharing.

For a given length password, yes, a randomly generated password with a large character set *will* have more entropy than four dictionary words.

Of course, most people aren't willing to memorize a long random password or use a password manager, so it is what it is.

oh tutanota is on nostr :o

hunter2

Nice OG meme reference

⚡️

nostr:npub1a76kz9rpksup2tye06uf67w2gffyvmp70q7je0fluxukul20xjpq473kkt Seems like this technique could be easily bruteforced by a dictionary attack, despite being a longer number of characters.

Personally (I'm no expert) I use a password manager. Most of my passwords are 128 characters (longer than four average words) that also use special characters, numbers, upper and lower case characters. Using a physical key such as a #Yubikey seems a better way, too.

I love #XKCD, but the advice in this strip seems kinda out of date.

⚡️

Get0nupandgetonouttahere!

We need to comic generator to replace those 4 words per individual...